Case Library / Deepfake & Synthetic Media / LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)

LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)

An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the red flags, ignored it, and reported it to security, so the attempt caused zero impact.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In April 2024, LastPass disclosed that one of its employees had been targeted in a social engineering attempt that used an audio deepfake to impersonate the company's CEO, Karim Toubba. The employee received a series of WhatsApp communications, including missed calls, texts, and at least one voicemail, from an account posing as Toubba. The voicemail featured AI-generated audio designed to sound like the CEO, applying pressure through a sense of urgency.

The employee did not comply. Because the contact arrived over WhatsApp, which is not a normal LastPass business communication channel, and because it carried classic social engineering hallmarks such as forced urgency and contact outside normal business hours, the employee grew suspicious, ignored the messages, and reported the incident to the internal security team.

LastPass stated plainly that there was no impact to the company. The security team was able to mitigate and, notably, LastPass chose to publish the incident on its own blog (authored by senior principal intelligence analyst Mike Kosak on April 10, 2024) specifically to raise awareness that deepfake tools are now cheap and accessible enough to be used in run-of-the-mill executive-impersonation fraud, not just by nation-state actors. Press reporting (BleepingComputer, SecurityWeek, PCMag) noted the cloned voice was likely generated from publicly available recordings of Toubba, such as podcast or video appearances.

This was an attempted attack that was blocked at the human layer. It also stands out because LastPass, a security company that had suffered major breaches in 2022, transparently used its own near-miss as a teaching case for the wider industry.

How the Attack Worked

Recon: the attacker obtained the target employee's contact details and identified LastPass's CEO as a credible impersonation target, drawing on the CEO's public profile and publicly available audio of his voice. Contact: the approach came through WhatsApp, a channel outside sanctioned corporate communications, using an account set up to appear as the CEO. Rapport and exploitation: the attacker layered multiple touches (missed calls, texts, and a voicemail) and used an AI-generated clone of the CEO's voice to lend authenticity, paired with manufactured urgency to push the employee to act quickly and without verification. Payout: the intended end state was executive-impersonation fraud, but the chain broke at the exploitation stage. The employee recognized the combination of an unusual channel, off-hours timing, and pressure tactics as a social engineering attempt, disengaged, and escalated to internal security, which neutralized the threat. Described at awareness altitude only, this record does not include any voice-cloning or setup instructions.

The Lure & the Tell

Pretext: an urgent request from someone presenting as the company CEO, delivered via a cloned voice to make the demand feel personal and legitimate. Visible red flags (tells): contact through WhatsApp rather than approved internal channels, outreach outside normal business hours, forced urgency pressuring an immediate response, and an unsolicited, out-of-band request from a senior executive to a mid-level employee. Any one of these should trigger out-of-band verification; together they were enough for the employee to reject and report the contact.

Outcome

Attempt fully blocked. No funds lost, no systems accessed, no impact to LastPass. The employee ignored the messages and reported to internal security; LastPass mitigated the threat, shared indicators with intelligence-sharing partners and peer security companies, and published the incident publicly to raise industry awareness.

Why It Matters

This is a clean example of an AI voice deepfake attack defeated at the human layer, showing that security awareness and a strong reporting culture remain effective even against synthetic-media attacks. It also marks a shift the industry had been warning about: deepfake voice fraud is no longer confined to nation-state actors or headline mega-losses (like the 2024 Hong Kong $25M video-deepfake case), but is now a commodity tactic used in everyday executive-impersonation attempts. That a security vendor itself was targeted, and chose to disclose a mere attempt with no losses, makes it a rare, citable teaching case.

Defenses

Out-of-band verification: confirm any urgent or unusual executive request through an established, approved internal channel before acting, never through the channel the request arrived on. Channel discipline: treat requests arriving via non-sanctioned channels (personal WhatsApp, SMS) as inherently suspect. Recognize social engineering hallmarks: forced urgency, off-hours contact, and pressure to bypass process. No-blame reporting culture: make it easy and expected for employees to escalate suspicious contacts to security. Awareness training that specifically covers AI voice cloning, so a familiar-sounding voice is no longer treated as proof of identity. Executive-impersonation playbooks and code words / verification protocols for high-stakes requests.

Sources
  • Attempted Audio Deepfake Call Targets LastPass Employee. LastPass (official blog, by Mike Kosak, Sr. Principal Intelligence Analyst) Primary. First-party incident disclosure published April 10, 2024. Confirms WhatsApp channel, calls/texts/voicemail, CEO impersonation via audio deepfake, forced urgency, employee reported it, zero impact to the company, and that LastPass shared the incident with intelligence-sharing partners and other cybersecurity companies. Verified by direct fetch.
  • LastPass: Hackers targeted employee in failed deepfake CEO call. BleepingComputer Secondary. Corroborates CEO Karim Toubba as the impersonated executive, quotes Kosak directly, and notes the clone was likely trained on publicly available audio of the CEO (citing a specific YouTube video) and that WhatsApp being an uncommon business channel helped the employee spot it. Also notes LastPass's 2022 breaches. Verified by direct fetch.
  • LastPass Employee Targeted With Deepfake Calls. SecurityWeek Secondary. Corroborates the incident occurred on a Wednesday in the week of April 10, 2024 (confirmed as the correct weekday for that date), that LastPass is owned by GoTo, and that the attempt failed due to the employee's suspicion of forced urgency and off-hours contact. Verified by direct fetch.
  • Scammers Target LastPass Employee With CEO Audio Deepfake. PCMag Secondary. Corroborates the fraudster created a WhatsApp account posing as Toubba, obtained the employee's contact details, and sent missed calls plus at least one AI voice message. Verified by direct fetch.
  • What CIOs Can Learn from an Attempted Deepfake Call. InformationWeek Secondary. Reports the targeted employee was a sales executive and emphasizes that a simple report to internal security stopped the attack early; includes commentary from LastPass's Mike Kosak on the company's awareness culture. Verified by direct fetch.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: the attacker plausibly gathered the target employee's contact details and identified LastPass's CEO, Karim Toubba, as a credible impersonation target, drawing on his public role and profile and, per press reporting, likely on publicly available audio of his voice such as podcast or video appearances.
Countering Stage 1: employee-facing OSINT exposure (executive names, roles, public appearances) is very hard to eliminate at enterprise scale for anyone publicly identified as a company's CEO; the realistic control assumes attackers already have this and hardens the process it later gets used against, rather than trying to hide it.
2
Voice-Clone and Impersonation-Infrastructure Setup: consistent with press reporting, the attacker likely used a commercially available or freely accessible AI voice-cloning service to generate synthetic audio mimicking the CEO's voice from those public recordings, and registered a WhatsApp account presenting as the CEO to serve as the delivery channel.
Countering Stage 2: an organization has little ability to stop a third party from using commercial voice-cloning tools or registering a look-alike messaging account; the nearest practical control is the same one used later in the chain, treating a synthetic-sounding voice as never sufficient proof of identity on its own.
3
Initial Multi-Touch Contact: the attacker reached the employee through WhatsApp, a channel outside LastPass's sanctioned business communications, opening with a series of missed calls and text messages from the account posing as the CEO.
Countering Stage 3: channel discipline. Requests arriving over personal messaging apps like WhatsApp rather than approved internal business channels should be treated as inherently suspect, regardless of who they claim to be from.
4
Pretext Delivery With Pressure: the attacker followed up with at least one voicemail carrying the AI-generated deepfake audio of the CEO's voice, applying forced urgency to push the employee toward an immediate, unverified response.
Countering Stage 4: security awareness training that specifically covers AI voice cloning and classic social engineering hallmarks (forced urgency, off-hours contact, pressure to bypass normal process), paired with a no-blame reporting culture that makes it easy and expected for employees to escalate suspicious contacts rather than act on them.
5
Intended Payout (blocked before execution): the likely end goal was an executive-impersonation fraud outcome, such as a fraudulent transfer or a credential/access request, but LastPass's disclosure does not describe a specific ask ever being made or acted on. The employee recognized the unusual channel, off-hours timing, and urgency as social engineering hallmarks, disengaged without complying, and reported it to internal security, so the chain never reached completion.
Countering Stage 5: mandatory out-of-band verification, contacting the purported executive or a known security channel through an already-established method, never the channel the request arrived on, before acting on any urgent or unusual request; executive-impersonation playbooks and pre-agreed verification protocols for high-stakes asks. This is the control that actually stopped the attempt: the employee's disengagement and report to internal security closed the chain before any payout could occur.
Quick Facts
Victim
LastPass (password management company, owned by GoTo); the direct target was a LastPass employee, reported by press as a sales executive. The impersonated executive was CEO Karim Toubba.
Location
United States (LastPass is US-headquartered); contact delivered remotely via WhatsApp
Date
2024-04
Impact
$0 (no loss; attempt blocked)
Status
Confirmed
Case Type
Real-World Incident
Sector
Technology & Software
Related

Related Cases

KnowBe4 Unknowingly Hires a North Korean Fake IT Worker Using an AI-Enhanced Photo and Stolen Identity

KnowBe4 unknowingly hired a North Korean operative for a software engineering role after he passed four video interviews using an…

Incident 2024Read →

FBI IC3 Advisory: Criminals Use Generative AI to Facilitate Financial Fraud (PSA241203)

The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning, and deepfake…

Incident 2024Read →

Arup Hong Kong Deepfake CFO Video-Call Fraud (HK$200M / US$25.6M)

A finance employee in Arup's Hong Kong office wired HK$200M (~US$25.6M) after a video conference in which the CFO and…

Incident 2024Read →